Sagan critical stable other
[WINDOWS-POWERSHELL] PowerShell Retrieve Users
[WINDOWS-POWERSHELL] PowerShell Retrieve Users
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] PowerShell Retrieve Users"; program:*PowerShell*; event_id:4103,4104; content:"System.DirectoryServices.ActiveDirectory.Domain"; nocase; content:"
| 28
| objectcategory=computer
| 29 28 7c 28
| lastlogon"; nocase; reference:url,https://trustedsec.com/blog/targeted-active-directory-host-enumeration; classtype:trojan-activity; sid:5014324; rev:1; metadata:deployment Server,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2024_02_28, updated_at 2024_02_28, mitre_tactic_id TA0007, mitre_technique_id T1087;) Field Validations
Loading…
Comments (0)
Loading comments...